Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions

Blog post from Socket

Post Details
Company
Date Published
Author
John Tuckner
Word Count
705
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

In May 2026, GitHub revealed a security breach involving the exfiltration of approximately 3,800 internal repositories through a compromised VS Code extension, highlighting the risks posed by third-party editor extensions. The malicious extension, Nx Console 18.95.0, was distributed via trusted marketplaces before its removal, underscoring the need for enhanced security measures to protect developer environments. Socket has responded by extending its Firewall protection to editor extensions, offering install-time and update-time control points to block malicious extensions before they are downloaded or run. This solution, now available in beta for Socket Enterprise customers, applies enforcement at the proxy level without requiring additional software deployment on developer devices, supporting both VS Code Marketplace and Open VSX ecosystems. By filtering requests and blocking flagged extensions, Socket Firewall aims to close the gap in extension security, ensuring that only safe extensions are installed and reducing the risk of credential theft and other security threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Developer Experience 1 404 252 100 -15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.